Description
A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.
Published: 2026-09-08
Score: 7.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Patch Upgrade
AI Analysis

Impact

The flaw resides in MongoDB Server's LDAP authorization integration. Pooled LDAP connections may hold a stale authenticated identity after a successful user login when certain configurations are active. When subsequent authorization requests are processed, the server may use the wrong LDAP identity, leading to role assignments that do not match the intended access control rules. This unintended privilege escalation is a form of authorization bypass, classified as CWE‑863.

Affected Systems

MongoDB Server is affected. No specific version ranges are listed; all deployments that use the LDAP authorization feature and employ pooled connections are potentially vulnerable.

Risk and Exploitability

The vulnerability carries a CVSS score of 7.6, indicating moderate to high risk. The EPSS score is unavailable, but the issue is not in CISA’s KEV catalog, suggesting limited public exploitation data. The attack vector is inferred to involve an authenticated user able to trigger LDAP authentication under a configuration that enables connection pooling; the attacker could thus obtain elevated privileges over the deployment’s authorization policy.

Generated by OpenCVE AI on September 8, 2026 at 18:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the MongoDB Server to a version that includes a fix for the LDAP connection pool identity management issue.
  • Review and adjust the LDAP connection pooling settings: either disable pooling or enforce a fresh authentication for each authorization query to prevent identity reuse.
  • Enable continuous monitoring of role assignments and audit logs to detect any unexpected privilege gains, and apply least‑privilege role definitions as a safeguard.

Generated by OpenCVE AI on September 8, 2026 at 18:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 16 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb mongodb
CPEs cpe:2.3:a:mongodb:mongodb:*:*:*:*:*:*:*:*
cpe:2.3:a:mongodb:mongodb:9.0.0:alpha0:*:*:-:-:*:*
cpe:2.3:a:mongodb:mongodb:9.0.0:alpha1:*:*:-:-:*:*
Vendors & Products Mongodb mongodb

Tue, 08 Sep 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared Mongodb
Mongodb mongodb Server
Vendors & Products Mongodb
Mongodb mongodb Server
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Description A security issue exists in MongoDB's LDAP authorization integration where pooled LDAP connections can retain stale authentication identities after user authentication under certain configurations. Subsequent authorization queries may execute under an unintended LDAP identity rather than the expected one. This can result in incorrect role assignments based on the LDAP directory's access control configuration, potentially allowing an authenticated user to acquire elevated privileges that were not intended by the deployment's authorization policy.
Title Improper Session Handling in MongoDB Server LDAP Authorization Integration Leads to Incorrect Role Assignment
Weaknesses CWE-863
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

cvssV4_0

{'score': 7.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Mongodb Mongodb Mongodb Server
cve-icon MITRE

Status: PUBLISHED

Assigner: mongodb

Published:

Updated: 2026-09-10T03:56:50.352Z

Reserved: 2026-08-27T22:50:39.457Z

Link: CVE-2026-82053

cve-icon Vulnrichment

Updated: 2026-09-08T17:55:46.402Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:33.143

Modified: 2026-09-16T20:40:31.170

Link: CVE-2026-82053

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T18:30:04Z

Weaknesses